Article
Troubleshoot AD Lockouts with PowerShell
Use events 4740 and 4625 together to move from 'the account keeps locking' to a timeline that identifies the source device, logon type and stale credential.
Topic
3 matching entries across Articles, TIL and Projects.
Long-form writing tagged Active Directory.
Use events 4740 and 4625 together to move from 'the account keeps locking' to a timeline that identifies the source device, logon type and stale credential.
NO_CLIENT_SITE entries in Netlogon logs are useful evidence that client networks are not mapped cleanly to Active Directory sites. PowerShell can turn the logs into a subnet-hygiene report.
Short notes and fixes tagged Active Directory.
Why Active Directory exposes multiple logon attributes and why choosing the wrong one can give misleading results.